Building in the open

Secure every AI call before it does damage.

SentinelAI.NET is an open-source runtime security gateway for .NET AI apps and agents. It inspects prompts, retrieved content, model output and tool calls, enforces policy, and emits OpenTelemetry evidence.

.NET nativeBring your own scannersSelf-hosted
CHECKPOINT / 01● ENFORCING
Your .NET app SENTINELgateway · YARP LLM / Agent Scanners (BYO) OpenTelemetry → SIEM promptallowscoreevents
One policyEvery hop inspected
● Allow● Redact● Block● Require approval● Trace everything
The enforcement loop

One loop, five stages.

Every request crosses four surfaces. Each is scanned, decided and recorded. Select a stage.

Architecture

The full capability map.

Each package exposes focused capabilities. Select a card for the contract and a sample.

CurrentPlannedContext
Live demo

Four attacks. Four outcomes.

Illustrative output of the v0.1 demo scenarios.

Quick start

Two lines. Policy in config.

Add the middleware, then let security teams own the YAML. No redeploy to change a rule.

Program.cs
// register
builder.Services.AddSentinelAI(o =>
{
    o.EnablePromptInjectionDetection();
    o.EnablePiiProtection();
    o.EnableToolAuthorization();
    o.EnableOpenTelemetry();
});

// enforce
app.UseSentinelAI();
sentinel.yaml
security:
  promptInjection:
    action: block
    threshold: 0.85
  pii:      { action: redact }
  secrets:  { action: block }
  toolCalls:
    delete_customer:
      action: require_confirmation
Why Sentinel

Not another scanner. The missing layer.

Strong tools already exist for detection, testing and observability. None combine .NET-native enforcement, a gateway and a tool firewall.

ToolStrengthWhat Sentinel adds
PromptfooRed teaming and CI testingProduction runtime enforcement
LlamaFirewallRuntime scannersRuns as a pluggable scanner behind policy
NeMo GuardrailsInput, output and tool rails.NET-native, no Python service to run
Langfuse · OpenLLMetryLLM observabilitySecurity decisions on the same traces
YARP · Extensions.AIProxy and AI abstractionsBuilt on top of both
Roadmap

Narrow first, then wider.

v0.1

Core gateway

Middleware, YARP, YAML policy, regex/PII/HTTP scanners, OTel events.

v0.2

Tool firewall

Per-tool authorization, argument validation, approval workflow.

v0.3

Scanner adapters

PromptGuard, LlamaFirewall, Azure Content Safety, ONNX.

Later

Client SDK

Optional Angular telemetry. Deliberately outside the MVP.

Put a checkpoint in front of your agents.

dotnet add package SentinelAI.AspNetCoreStar on GitHub ↗